Impact
The vulnerability arises during the handling of video data that contains unusually large offset and length values. These values cause the internal copy operation to write beyond the bounds of the allocated buffer, leading to an out‑of‑bounds write. This memory corruption can compromise the integrity of the running system, potentially allowing an attacker to overwrite critical memory structures and execute arbitrary code or crash the application.
Affected Systems
Qualcomm, Inc. Snapdragon devices are affected. Specific models and firmware releases impacted are not detailed in the CVE data, and no version range is provided.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity. The EPSS score of less than 1% suggests a low probability of exploitation at present, and the vulnerability is not yet listed in CISA’s KEV catalog. Based on the description, the likely attack vector is local or via a malicious video stream processed by the affected device; exploitation requires delivery of a crafted video payload with oversized offset and length values. The attack complexity appears moderate, and success would grant the attacker code execution or a denial of service in the compromised system.
OpenCVE Enrichment